Guide7 min read

Is It Safe to Use AI for Museums?

Yes for generic work, no with your records: never expose a donor promised anonymity or confidential provenance to a consumer AI. You are the controller.

By Pierre de ONYRI

The answer fits in one line. AI can draft catalogue text or a fundraising appeal, but never hand it your real records. A museum holds very sensitive data. A donor's name and giving history. A collector's or lender's details. A provenance that is sometimes contested. Your member and visitor data. Under the GDPR, your institution is the controller of that data. Pasting a donor list into a consumer ChatGPT can expose an identity promised anonymity. That is a broken promise, not a technicality. There is a clean method: anonymise the identifiers before any prompt.

Museums hold more sensitive data than you think

We picture a museum as a keeper of objects. It is also a keeper of personal data. The development team tracks every major donor. Name, giving history, sometimes a wealth estimate. The loans register lists private collectors. These owners of valuable works prize their privacy. Provenance files trace the chain of ownership, sometimes through sensitive restitution cases.

This information moves fast when a team tries AI. They ask it to summarise a patron file. To draft a targeted appeal. To sort a member spreadsheet. The gesture feels harmless. It is not. Every name pasted in leaves your control and joins a third-party tool.

  • Donor records: name, giving history, wealth screening estimates.
  • Collectors and lenders: confidential details of owners of valuable works.
  • Provenance and acquisitions: chain of ownership, sometimes tied to restitution cases.
  • Members, subscribers and visitors: personal data under the GDPR.
  • Archives and research: data on living, identifiable people.

The museum is the controller of its data

The law names a clear owner. Under the GDPR, whoever decides the purposes and means of processing is the controller. That is the highest level of responsibility. The ICO, the UK's data protection regulator, puts it plainly. The controller must comply with all the principles and demonstrate that compliance. A museum that collects donor, member and visitor data and decides how to use it is the controller of that data.

That responsibility does not vanish when you hand data to a tool. Per the ICO, the controller stays responsible for the compliance of any processor it uses. A processor only acts on the controller's documented instructions. That is why an external tool requires a contract setting out those instructions. In practice, a data processing agreement (DPA) before any personal data changes hands.

Charitable status changes nothing. The UK Fundraising Regulator makes the point. Charitable and fundraising bodies have the same data protection duties as commercial organisations. The charitable purpose does not remove them. You need a lawful basis to contact donors and supporters. And you must be open about how information is used and who it is shared with.

The anonymous donor: a promise, not a checkbox

Some donors require anonymity. That is a confidentiality commitment made by the museum. Exposing that identity through an external system fails the transparency, security and fairness duties the controller owes that person. It is not a technical slip. It is a broken promise. A donor list pasted into a consumer AI can reveal the very name you swore to keep quiet.

Take care not to blur two ideas. Wealth data and giving history are sensitive and must be secured. But under the UK GDPR, they are not special category data within the meaning of Article 9. That special list is narrow: health, racial or ethnic origin, religious beliefs and biometric data, among others. It needs a lawful basis under Article 6 AND a separate Article 9 condition.

The distinction matters for a museum. A medical record in an archive can cross into special category territory. So can a provenance file on looted art that reveals a person was Jewish. That is then data on ethnic origin or religion, so special category. Treat wealth as sensitive, but reserve Article 9 for cases of health, origin or belief.

You assumeThe reality
“Summarising a patron file is risk-free”The museum is the controller; that data shouldn't leave without a DPA
“A donor's anonymity is just an option”It's a commitment of confidentiality, security and fairness
“A charity has fewer obligations”The Fundraising Regulator: the same duties as businesses
“A donor's wealth is special category data”No: sensitive and to be secured, but outside Article 9
The risk isn't using AI — it's the identities and records you leave behind in the prompt.

Security, minimisation and living people

Two GDPR principles guide good practice. Minimisation first. Collect and keep only the minimum data, and no longer than necessary. That is a reason not to expose a whole donor or member list to a third-party tool with no need for the full record. Security next. Financial details must be protected by appropriate measures.

Do not forget archives and research. Data on living, identifiable people there is still personal data under the GDPR. The historical or scientific nature of the material does not, by itself, remove those individuals' rights. An acquisition file or a researcher record can therefore hold protected data.

A word on physical security. Details of high-value works and their locations are a theft risk. This is not first a data protection matter, but an operational security one. All the more reason never to paste a precise location into a tool you do not control.

The fix: anonymise before you send

Good news: AI is still useful for the museum. It drafts catalogue text, a fundraising appeal, a visitor reply. On de-identified text, it does all that work without seeing a single real name. Ask in neutral terms. Keep donors, collectors, lenders and members out of the prompt.

Two-part diagram: at top, a donor and provenance record (a name, a giving amount, an “anonymity requested” note) in the clear in amber, beside a museum column, travels toward an AI card that receives the exposed record with an amber alert; at bottom, the same record anonymised shows only cobalt tokens, and the AI receives only tokens with a checkmark under a shield.
After ICO guidance (controllers/processors and special category data) and the Fundraising Regulator on fundraising confidentiality.

When you must include a concrete case, anonymise it first. Replace each identity with a token. The AI reasons about the shape of your record, without ever seeing the real values. You restore the real values afterwards, locally.

  1. 1Spot the identities in your text: donors, collectors, lenders, members.
  2. 2Never paste an anonymous-donor identity or confidential provenance.
  3. 3Replace each identifier with a reversible token, in the browser.
  4. 4Send only the anonymised text, and use only tools bound by a DPA.
  5. 5Restore the real values in the reply, locally.

That's what ONYRI Sanitize is for. The engine detects sensitive data — donor names, collector details, amounts, member identities — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI finds only tokens, never the identity of a donor promised anonymity. You get the help, without betraying the confidentiality your museum owes, as controller, to those who trust it.

Frequently asked questions

Is it safe to use AI for museums?
Yes for generic work, no with your real records. AI can draft catalogue text or a fundraising appeal on de-identified text. But never expose a donor promised anonymity, confidential provenance or a member list to a consumer AI. Under the GDPR, your museum is the controller of that data. Anonymise the identities before you send.
Is pasting a donor list into ChatGPT a real problem?
Yes, it can be. A donor promised anonymity gave you a confidentiality commitment. Exposing them through an external tool fails your security and fairness duties. What's more, a free consumer chatbot is usually bound by no DPA. So you would hand personal data to a third party without the contract the GDPR expects of you. Replace each identity with a token before you send.
Is a donor's wealth data special category data?
No. Wealth and giving history are sensitive personal data that must be secured, but they fall outside Article 9 of the GDPR. The special category list covers health, origin, religion or biometric data. By contrast, a medical archive record or a provenance file revealing a person's origin or religion can be special category.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next